Direct answer

A PIA is a dated report with risks and mitigations — not a one-line ‘we assessed it’.

PIPL requires a personal information protection impact assessment before processing SPI, using PI for automated decision-making, entrusting processing, providing PI to other handlers, disclosing PI, or transferring PI abroad, and in other high-risk cases. The report should cover legality, necessity, impact on rights, security measures and residual risk, and be retained (the statute speaks in years, not days). A GDPR DPIA can be a source file; it is not a PIPL PIA until the PIPL questions are answered. CAC assessment for export is a different, regulator-facing process.

The classification screen

4 questions before you choose the route.

This page identifies the right question and evidence. It does not determine the legal outcome on a reader’s facts.

01

Is a PIA triggered?

SPI, export, ADM, entrusted, disclosure.

Trigger
02

Who signs it?

Handler, not only the vendor.

Owner
03

What residual risk remains?

If high, do not process yet.

Risk
04

Retention of the report?

Keep it; CAC/export files may need it.

File

Working rule: Map the regulated role before marketing or launch in China.

What changes the answer

The signal ledger.

These facts move the question beyond a label and into a product, money-flow and control analysis.

Signal
Ask the operating question
Why it changes the route
DPIA rename
Did you change the title of a GDPR DPIA?
PIPL tests differ (separate consent, export tools).
Vendor PIA only
Did the SaaS send a generic PDF?
The handler still assesses this processing.
After-the-fact
Did export already happen?
That is an incident posture, not a PIA.
Prepare before you escalate

Bring a compact evidence docket—not a pitch deck.

Give a compliance team or counsel the operating facts that reveal the perimeter.

01Processing descriptionTypes, volume, recipients, destinations.
02Legal basesPIPL articles actually relied on.
03ControlsEncryption, access, retention, subprocessors.
Common confusions

Questions people ask before they build.

Short answers for orientation. The right result can change with the service model and current rules.

Is a PIA the same as CAC security assessment?

No. PIA is the handler’s internal statutory assessment. CAC security assessment is a regulator gate for certain exports.

How long to keep it?

PIPL requires retention of PIA reports for a statutory period (years). Keep them with version dates.

Primary authorities

Reviewed sources support orientation, not a fact-specific assessment.